download.nai.comConfirmation
http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip CVE-2004-0095
McAfee ePolicy Orchestrator 1.x/2.x/3.0 Agent - POST Buffer Mismanagement
Record summary
CVE-2004-0095 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMcAfee ePolicy Orchestrator 1.x/2.x/3.0 Agent - POST Buffer MismanagementExploitDB exploitby cyber_flashNot analyzed1 file
References
53744vdb entry
http://www.osvdb.org/3744 9476vdb entry
http://www.securityfocus.com/bid/9476 epolicy-contentlength-post-dos(14989)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/14989 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0095